OPINION:
Russian state-sponsored hackers have spent more than a decade quietly burrowing into the routers and networking devices that form the backbone of America’s critical and defense infrastructure.
A joint advisory released July 13 by the NSA, CISA, the FBI and intelligence agencies from more than a dozen allied nations confirms the threat is not receding.
Cyber actors linked to Russia are constantly and systematically scanning for poorly configured and vulnerable networking devices across the communications, energy, financial services, defense industrial base and healthcare sectors.
These attacks do not require sophisticated exploits to get in. They are walking through doors that were left unlocked years ago, exploiting default passwords and legacy protocols that organizations simply never got around to fixing.
The pattern should concern every policymaker in Washington. Adversaries are not just probing America’s critical infrastructure from the outside. They are mapping it from within.
The conditions that made this possible did not develop overnight. This campaign exposes the real cost of decades of uneven investment in America’s cyber defenses.
The technical networks of the American government and the critical infrastructure that powers our modern society carry decades of accumulated tech debt: deferred maintenance, unpatched vulnerabilities and systems designed for a bygone era. Over time, successive administrations, agencies and technology providers have built, rebuilt and adapted parts of these systems while other parts remained largely unchanged.
The result is not the failure of any one participant. It is a patchwork shaped by incremental evolution, uneven modernization, budget constraints, and threat environments that no longer exist.
Artificial intelligence has made the situation more urgent. AI tools now enable adversaries to find vulnerabilities at scale, automate reconnaissance that once required skilled human operators, and craft deception faster than most organizations can detect.
The balance of power has shifted in favor of the attacker. The time between an attacker breaching a network and reaching its most sensitive systems has been compressed from weeks to minutes. Our enemies do not need to be perfect; they just need to get it right once. We must be perfect.
The Trump administration is taking steps in the right direction. The national cyber strategy released in March recognized that cybersecurity is a core element of national defense. In June, President Trump asked Congress for additional defense dollars, including $5.1 billion for cybersecurity and autonomous capabilities to secure networks, software and infrastructure, as well as offensive capabilities.
Executive orders on AI and network security have directed agencies to accelerate zero-trust transitions, modernize aging federal systems and expand the cybersecurity workforce. These are substantive commitments and reflect recognition that cyber defense is a standing national security requirement, not a discretionary budget item.
However, the government cannot close this gap alone. The scale of the problem requires sustained partnership with the private sector that builds, operates and secures much of the nation’s digital infrastructure.
In February, the Missile Defense Agency selected IBM and other U.S. tech companies to support the modernization of American homeland defense systems, bringing AI and advanced cybersecurity capabilities to one of the most sensitive missions in the defense portfolio.
Companies such as Booz Allen are investing hundreds of millions of dollars in developing new defensive tools to help protect America’s critical infrastructure. American innovators leading the world in AI development are also using this technology as a critical defense tool to combat cyber threats.
These are not isolated efforts. Across the defense industrial base, American technology companies are investing in the capabilities the threat environment demands.
What remains is the question of pace. Congress must begin treating cybersecurity as an arsenal requirement on par with ships, aircraft and munitions. Federal agencies must accelerate the modernization of their networks while ensuring that the companies they partner with build to the same standard.
Industry must keep investing in the capabilities and the workforce the threat environment demands — not to check a compliance box, but to keep pace with adversaries who are not waiting.
The U.S. has won past technological revolutions because it chose to lead. We built the ships, aircraft, satellites, sensors and precision weapons that kept our enemies cautious for generations. Now we must build the digital defenses and AI-enabled capabilities that will do the same.
However, we are running out of time. Congress must fund cyber defense as a standing requirement of national security, and industry must build as if the next attack is already underway — because it is.
• Keith Kellogg is a co-chair for American security at the America First Policy Institute and a former special presidential envoy to Ukraine. He served as assistant to the president, U.S. National Security Council chief of staff and national security adviser to Vice President Mike Pence during President Trump’s first administration. He is a retired U.S. Army lieutenant general who commanded the Army’s 82nd Airborne Division.

Please read our comment policy before commenting.